workflow-metrics

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a quantitative scoring system for creative projects. Its instructions are purely logical and do not contain prompt injection attempts or efforts to bypass safety guardrails.
  • [DATA_EXFILTRATION]: The skill reads project state files (project_state.json and decision_log.md) to extract metrics. These operations are limited to the local environment, and no network tools (like curl or wget) or external domains are referenced in the instructions.
  • [COMMAND_EXECUTION]: The skill specifies scoring logic in pseudo-code (Python/JSON format), but these are provided as instructions for the agent to follow rather than executable shell scripts. No risky subprocess or system-level commands were detected.
  • [REMOTE_CODE_EXECUTION]: There are no external dependencies, package installations, or remote script fetches. The skill is entirely self-contained within the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — workflow-metrics